Definition · DNS & Email Spoofing

What is Typosquatting?

Typosquatting is the deliberate registration of domains that closely resemble a legitimate domain — misspellings, adjacent-key typos, missing or doubled letters, or plausible variations. Users who mistype an address, or who fail to spot the difference in a link, land on infrastructure the attacker controls.

Common typosquatting patterns

  • Character omission or doubling — exmple.com, exaample.com
  • Adjacent-key typos — ecample.com
  • Character swaps — examlpe.com
  • Different TLDs — example.co, example.net when the brand uses .com
  • Added words or hyphens — example-login.com, examplesupport.com
  • Visually similar characters — covered separately as homoglyph attacks

How typosquatted domains are abused

Beyond capturing stray traffic, lookalike domains are the raw material of phishing: they host credential-harvesting pages styled after the real brand and provide believable sender addresses for email attacks against staff, customers, and suppliers. Because the attacker owns the domain outright, they can configure valid SPF, DKIM, and DMARC for it — authentication proves the mail came from the lookalike domain, not that the domain is honest.

Defences

Organisations defensively register the most obvious variants, monitor new domain registrations and Certificate Transparency logs for lookalikes, and pursue takedowns through registrars or UDRP proceedings when abusive domains appear. Training users to check domains carefully helps, but detection and takedown remove the threat at source.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.